Live data from Hacker News

IoT hacking and rickrolling my high school district

whitehoodhacker.net

301–310 of 399 posts

Re: IoT hacking and rickrolling my high school district

#301
post #244

I feel so dumb when I read kids doing these things. Back in High School all I knew was how I could run arbitrary executable files by renaming them to calc.exe. We also did the classic "take a screenshot of the desktop, set it as the wallpaper, then remove all icons and the start menu" thing.

Another good one on that level was using the Windows keyboard shortcut ctrl-alt-down to rotate the display upside down - totally harmless, but absolutely maddening if you don’t know how to undo it

Even better if you combined it with an upside down screenshot of the desktop. So it looked like only the mouse was upside down and all buttons didn't work.

Re: IoT hacking and rickrolling my high school district

#302
post #258

Earlier quoted context omitted.

Not really. Sounds like this was class of '08, and at the time BackTrack would have been readily available and popular enough for a curious highschooler with a bit of computing background to find. As I recall etercap was built in and I wouldn't be at all surprised if there were tutorials for setting up scenarios almost exactly like what is described. Even the ARP balancing thing is the kind of too-clever-by-a-half so…

Maybe they hardcoded the real gateway's MAC Address.

They did not: https://news.ycombinator.com/item?id=28846569

Re: IoT hacking and rickrolling my high school district

#303

Working in IT/tech for school district is the worst. My experience from many years ago - around 2002, I think: 1. First day on the job, email to boss: "Hey, the computer lab at Springfield High has a ton of known security flaws that are begging to be exploited." 2. Reply, 1 week later: "Sorry, we don't have any money for that. Just keep everything up-and-running." 3. 3 weeks later the computer lab at Springfield High…

> we don't have any money for that They always have the money. They just don't care about doing things properly. It simply isn't a priority for them. Makes me feel good when someone comes and exploits their negligence. It's like divine retribution and they're doing god's work. They tempt fate and the gods punish them by making them pay more than they would have paid had they done things right. Amazing.

Except they don't pay themselves, that's why they don't care.

Re: IoT hacking and rickrolling my high school district

#304
post #293

Earlier quoted context omitted.

> All the computers displayed a popup window When I engaged in `net send` shenanigans at the local community college, at least the IT staff was smart enough to know where to scramble a runner whenever those dialog boxes popped up across campus. "ALL YOUR BASE ARE BELONG TO US" was quite the meme then, but apparently they thought it was some form of cyber-terrorism.

When I had my net send fun back in school, an IT guy found me and just explained that if it becomes a recurring thing, they'll have to disable it on the network. And that they would prefer to keep the functionality available, so it would be a real shame if I ruined that for them. I never did another one, because I understood it would be a dick move. No condescension, no threats. Just treating me like an adult with a…

Ah good ol net send… we had a lot of fun in high school with that in the 90s

Re: IoT hacking and rickrolling my high school district

#305

Working in IT/tech for school district is the worst. My experience from many years ago - around 2002, I think: 1. First day on the job, email to boss: "Hey, the computer lab at Springfield High has a ton of known security flaws that are begging to be exploited." 2. Reply, 1 week later: "Sorry, we don't have any money for that. Just keep everything up-and-running." 3. 3 weeks later the computer lab at Springfield High…

I 'worked' for my own high school's IT dept, a few hours a week, as a student. It was an amazing experience working with those guys. I learned so many things, from how to punch, terminate, and run cables to how to set up a Ghost image and deploy it en masse across the district. One day one of the old macs was showing the frowny face in a in-session classroom. Boss sent me down there with specific instructions: "pull…

> ...pull out the HD. I beat it with the handle, like a good 10 times...

Heh. Nice.

A coworker's Mac wouldn't boot. I couldn't hear the hard drive. It was a model with the tip of the spindle exposed. I found a pencil with a gummy eraser. Gave the spindle a twist as I turned the power on.

Told the amazed user, "Do not turn off your computer until after you have backed up your data. That probably won't work twice."

Good times.

Re: IoT hacking and rickrolling my high school district

#306

I thought I was cool being able to modify the ready message on printers across the school network. This is really impressive.

In middle school I used Javascript to change Google's button text from "I'm feeling lucky!" to "Andrew is the best!" (javascript:getElementById('').text='blah') I showed some other students who were so freaked out that I had "hacked Google" that I got the attention of the librarian, who promptly banned me from the library computers for the rest of the year, even after I refreshed the page to show them it wasn't "real…

Haha when I was searching for printers across the district network the librarian was looking at my screen. She called me out across the room asking why I was looking at printers at a different school. Oof.

Re: IoT hacking and rickrolling my high school district

#307
Reminds me of when I attended my districts technical career center for 2 years. We had ~3 hours of various IT learning every morning with kids from high schools all over the county before we all went back to our normal schools.

We'd of course run out of stuff to do and start messing around with our newly honed skills. Learning about net send wasn't too bad, we just sent dumb messages to each other. But learning vbscript combined with net send... you could DoS the other machines with a for loop.

One morning I was playing around with the net send script, but accidentally plugged into the schoolwide LAN instead of our local network... every computer in the building got locked down with some idiotic message my 17 year old brain had come up with. IT took a educated guess and came down to our class and I fessed up, thankfully they let me off with a stern talking to and promises to never do it again.

Re: IoT hacking and rickrolling my high school district

#308
post #223

Earlier quoted context omitted.

The school district itself was relatively chill, however the individual deans freaked out. Because the penetration report was sent to the tech team and not the deans, the deans were intent on finding out exactly who did the hack to find something to report to their bosses (and according to them concern about the grade book system being exposed?? Not sure how you’re supposed to rick roll a grade book but if anyone has…

>and according to them concern about the grade book system being exposed?? Junior year in high school, I got suspended for "hacking." The tl;dr is that I was using a proxy to fetch assignments for class (because the county decided "yeah, this state run Moodle instance is obviously not appropriate for education" and one of my classes used Moodle) and got caught with the proxy configuration screen open. I wish I was jo…

yeah, those inner connections were really important. guess it was a good thing my brother was friends with the tech person at our school.

Re: IoT hacking and rickrolling my high school district

#309
I remember being in elementary school and avoiding the net nanny by viewing one of the network drives that students (somehow) had access to but weren't told about. Eventually, someone in my class poked around enough to find BESS.exe and deleted it and we had unfiltered internet for a day.

Re: IoT hacking and rickrolling my high school district

#310
post #223

Three things are remarkable about this, and make it a happy story. First, that the pranksters were so egregiously responsible in the way they went about it. They avoided disrupting any actual educational activities; it was meant to be harmless fun, not vandalism. No harm came to anything here. Second, that they documented their findings to the administration as part of the action, including recommendations for improv…

The school district itself was relatively chill, however the individual deans freaked out. Because the penetration report was sent to the tech team and not the deans, the deans were intent on finding out exactly who did the hack to find something to report to their bosses (and according to them concern about the grade book system being exposed?? Not sure how you’re supposed to rick roll a grade book but if anyone has…

> espite the fact that the only information they had to go off of was my youtube channel which had no references to my actual name whatsoever

Assuming you took the video at the top of the article, it was presumably trivial to figure out who was in the class you were in and then rule out everyone who appears on camera as the camera man. Or just ask the teacher...

Post reply on HN